Detection & Response Security Engineer, Threat Intelligence

Meta

City Of London

On-site

GBP 60,000 - 100,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Meta in London is hiring a threat intelligence investigator to proactively respond to cyber threats and track actor groups targeting Meta. You will work with cross-functional stakeholders to improve security posture and identify gaps in detections through intelligence-led research.

The role emphasizes intelligence-driven hunting, collaboration with incident responders, and development of countermeasures. Ideal candidates have 3+ years in threat intel, a CS/InfoSec degree, and hands-on experience

Qualifications

  • 3+ years threat intelligence experience.
  • Bachelor's degree in Computer Science, Information Security, or relevant field.
  • Familiarity with campaign tracking techniques and ability to convert tracking results to long term countermeasures.
  • Familiarity with threat modeling framework, such as Diamond Model and/or MITRE ATT&CK framework.
  • Experience intelligence-driven hunting to spot suspicious activities in the network and identify potential risks.
  • Proven track record of managing and executing on short term and long term projects.
  • Ability to work with a team spanning multiple locations/time zones.
  • Ability to prioritize and execute tasks with minimal direction or oversight.
  • Ability to think critically and qualify assessments with solid communications skills.
  • Coding or scripting experience in one or more scripting languages such as Python or PHP

Responsibilities

  • Track threat clusters posing threats to Meta's infrastructure and employees, and identify, develop and implement countermeasures on our corporate network
  • Investigate, mitigate, and forecast emerging technical trends and communicate effectively with actionable suggestions to different types of audiences
  • Work closely with incident responders to provide useful and timely intelligence to enrich ongoing investigations
  • Improve the tooling of threat cluster tracking and intelligence data integration to existing systems
  • Engage constructively in cross-functional projects to improve the security posture of Meta's infrastructure, such as red team operations, surface detection coverage expansion and vulnerability management discussions

Skills

Threat intelligence
Python
PHP

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

YARA
Snort

Job description

Meta Security is looking for a threat intelligence investigator with extensive experience in investigating cyber threats with an intelligence-driven approach. You will be proactively responding to a broad set of security threats, as well as tracking actor groups with an interest or capability to target Meta and its employees. You will also be identifying the gaps in current detections and preventions by long-term intelligence tracking and research, and working with cross-functional stakeholders to improve Meta's security posture.

Responsibilities
  • Track threat clusters posing threats to Meta's infrastructure and employees, and identify, develop and implement countermeasures on our corporate network
  • Investigate, mitigate, and forecast emerging technical trends and communicate effectively with actionable suggestions to different types of audiences
  • Work closely with incident responders to provide useful and timely intelligence to enrich ongoing investigations
  • Improve the tooling of threat cluster tracking and intelligence data integration to existing systems
  • Engage constructively in cross-functional projects to improve the security posture of Meta's infrastructure, such as red team operations, surface detection coverage expansion and vulnerability management discussions
Minimum Qualifications
  • 3+ years threat intelligence experience
  • Bachelor's degree in Computer Science, Information Security, or relevant field (or equivalent experience)
  • Familiarity with campaign tracking techniques and ability to convert the tracking results to long term countermeasures
  • Familiarity with threat modeling framework, such as Diamond Model and/or MITRE ATT&CK framework
  • Experience intelligence-driven hunting to spot suspicious activities in the network and identify potential risks
  • Proven track record of managing and executing on short term and long term projects
  • Ability to work with a team spanning multiple locations/time zones
  • Ability to prioritize and execute tasks with minimal direction or oversight
  • Ability to think critically and qualify assessments with solid communications skills
  • Coding or scripting experience in one or more scripting languages such as Python or PHP
Preferred Qualifications
  • Familiarity with malware analysis or network traffic analysis
  • Experience authoring production code for threat intelligence tooling
  • Experience conducting large scale data analysis
  • Experience in one or more query languages such as SQL
  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Experience working across the broader security community
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Production of file-based or network-based rules and signatures for detection and tracking of complex threats, such as YARA or Snort
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Experience closely collaborating with incident responders on incident investigations
  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
  • Familiarity with nation-state, sophisticated criminal, or supply chain threats
About Meta

Meta builds technologies that help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology. People who choose to build their careers by building with us at Meta help shape a future that will take us beyond what digital connection makes possible today-beyond the constraints of screens, the limits of distance, and even the rules of physics.

Equal Employment Opportunity

Meta is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. You may view our Equal Employment Opportunity notice here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection & Response Security Engineer, Threat Intelligence
Detection & Response Security Engineer, Threat Intelligence

Meta • City of Westminster

On-site
GBP 70,000 - 110,000
Detection & Response Security Engineer, Threat Intelligence
Detection & Response Security Engineer, Threat Intelligence

Meta • Greater London

On-site
GBP 60,000 - 95,000
Infrastructure Security Monitoring Engineer
Infrastructure Security Monitoring Engineer

Meta • Greater London

On-site
GBP 90,000 - 130,000
Security Program Manager, Exam and Audit
Security Program Manager, Exam and Audit

Meta • City Of London

On-site
GBP 120,000 - 180,000
Employment Investigator
Employment Investigator

Meta • Greater London

On-site
GBP 65,000 - 95,000
Data Scientist, Product Analytics
Data Scientist, Product Analytics

META • City Of London

On-site
GBP 90,000 - 140,000
Employment Investigator (Fixed Term)
Employment Investigator (Fixed Term)

Meta • Greater London

On-site
GBP 45,000 - 65,000
Case Manager, eDiscovery & Information Governance Team
Case Manager, eDiscovery & Information Governance Team

Meta • City Of London

On-site
GBP 90,000 - 130,000
Enterprise Technical Sales Specialist, EMEA
Enterprise Technical Sales Specialist, EMEA

META • Greater London

On-site
GBP 120,000 - 160,000
Security Engineer (Threat Intel)
Security Engineer (Threat Intel)

Anthropic • York and North Yorkshire

On-site
GBP 85,000 - 130,000
Health insurance
Fertility benefits
Parental leave (22 weeks)
+8